<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: CyberSpeak interview</title>
	<atom:link href="http://blog.didierstevens.com/2007/07/23/cyberspeak-interview/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2007/07/23/cyberspeak-interview/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Wed, 08 Feb 2012 19:23:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2007/07/23/cyberspeak-interview/#comment-11586</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Tue, 24 Jul 2007 18:14:49 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/23/cyberspeak-interview/#comment-11586</guid>
		<description><![CDATA[That is right, shifting a counter is a programmers hack, but using ROT13? You&#039;re clearly sending a message when you do this, but what kind of message?]]></description>
		<content:encoded><![CDATA[<p>That is right, shifting a counter is a programmers hack, but using ROT13? You&#8217;re clearly sending a message when you do this, but what kind of message?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: www.andrewhay.ca &#187; Suggested Blog Reading - Monday July 23rd, 2007</title>
		<link>http://blog.didierstevens.com/2007/07/23/cyberspeak-interview/#comment-11570</link>
		<dc:creator><![CDATA[www.andrewhay.ca &#187; Suggested Blog Reading - Monday July 23rd, 2007]]></dc:creator>
		<pubDate>Tue, 24 Jul 2007 11:52:02 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/23/cyberspeak-interview/#comment-11570</guid>
		<description><![CDATA[[...] CyberSpeak interview - Check out Didier&#8217;s interview. My interview on the CyberSpeak podcast about my UserAssist tool is up. I discovered I speak English with a French accent  But I’m not French, I’m Flemish! [...]]]></description>
		<content:encoded><![CDATA[<p>[...] CyberSpeak interview &#8211; Check out Didier&#8217;s interview. My interview on the CyberSpeak podcast about my UserAssist tool is up. I discovered I speak English with a French accent  But I’m not French, I’m Flemish! [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: keydet89</title>
		<link>http://blog.didierstevens.com/2007/07/23/cyberspeak-interview/#comment-11565</link>
		<dc:creator><![CDATA[keydet89]]></dc:creator>
		<pubDate>Tue, 24 Jul 2007 11:00:43 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/23/cyberspeak-interview/#comment-11565</guid>
		<description><![CDATA[The fact that the count field starts at 5 is strange, yes...but the whole issue about ROT-13 &#039;encryption&#039; is even stranger!  Why, of all keys, would those particular keys have values that are ROT-13 encrypted?

I have my own tools that get this information from NTUSER.DAT files extracted from forensic images.  I use these tools on a regular basis, and have even had cases recently were these tools were the starting point of my investigation.  A very interesting capability that I have added to the tools is the ability to sort the entries by their timestamp value, going from most recent and walking backward through time.  This functionality has been extremely helpful, particularly in intrusion or UAP violation cases, where the &quot;when&quot; of an activity is as important as the &quot;what&quot;.]]></description>
		<content:encoded><![CDATA[<p>The fact that the count field starts at 5 is strange, yes&#8230;but the whole issue about ROT-13 &#8216;encryption&#8217; is even stranger!  Why, of all keys, would those particular keys have values that are ROT-13 encrypted?</p>
<p>I have my own tools that get this information from NTUSER.DAT files extracted from forensic images.  I use these tools on a regular basis, and have even had cases recently were these tools were the starting point of my investigation.  A very interesting capability that I have added to the tools is the ability to sort the entries by their timestamp value, going from most recent and walking backward through time.  This functionality has been extremely helpful, particularly in intrusion or UAP violation cases, where the &#8220;when&#8221; of an activity is as important as the &#8220;what&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2007/07/23/cyberspeak-interview/#comment-11540</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Mon, 23 Jul 2007 19:19:24 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/23/cyberspeak-interview/#comment-11540</guid>
		<description><![CDATA[Yes, starting to count from 5 is strange. When programmers work with a counter and they need some special values that have another meaning than the actual numerical value, in &quot;the olden days&quot;, they would use something like 99. So they would attribute special meaning to the maximum values, not to the minimum values.

This technique caused some interesting bugs in 1999 and 2000 ;-)]]></description>
		<content:encoded><![CDATA[<p>Yes, starting to count from 5 is strange. When programmers work with a counter and they need some special values that have another meaning than the actual numerical value, in &#8220;the olden days&#8221;, they would use something like 99. So they would attribute special meaning to the maximum values, not to the minimum values.</p>
<p>This technique caused some interesting bugs in 1999 and 2000 <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://blog.didierstevens.com/2007/07/23/cyberspeak-interview/#comment-11539</link>
		<dc:creator><![CDATA[Dave]]></dc:creator>
		<pubDate>Mon, 23 Jul 2007 19:08:26 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/23/cyberspeak-interview/#comment-11539</guid>
		<description><![CDATA[I was intrigued to hear the process by which you have managed to identify what the elements of data in UserAssist mean (I realise there are more to clarify).  I guess it requires a painstaking logical approach to understand exactly  what happens, for instance, if a program is removed from the Start Menu.  I&#039;ve seen the Gates = 5 comment before and would really like to know the reason behind the count starting at 5 rather than 0.  I suspect that we&#039;ll never know the real reason.

Thanks for your explanation and hard work.]]></description>
		<content:encoded><![CDATA[<p>I was intrigued to hear the process by which you have managed to identify what the elements of data in UserAssist mean (I realise there are more to clarify).  I guess it requires a painstaking logical approach to understand exactly  what happens, for instance, if a program is removed from the Start Menu.  I&#8217;ve seen the Gates = 5 comment before and would really like to know the reason behind the count starting at 5 rather than 0.  I suspect that we&#8217;ll never know the real reason.</p>
<p>Thanks for your explanation and hard work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2007/07/23/cyberspeak-interview/#comment-11534</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Mon, 23 Jul 2007 18:10:02 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/23/cyberspeak-interview/#comment-11534</guid>
		<description><![CDATA[Thanks Harlan!

I&#039;ve also been pondering the malicious and mischievous possibilities of the UserAssist keys, but I don&#039;t know about any malware exploiting these keys. I&#039;ve searched for UserAssist in a couple of virus description databases, but without success.]]></description>
		<content:encoded><![CDATA[<p>Thanks Harlan!</p>
<p>I&#8217;ve also been pondering the malicious and mischievous possibilities of the UserAssist keys, but I don&#8217;t know about any malware exploiting these keys. I&#8217;ve searched for UserAssist in a couple of virus description databases, but without success.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: keydet89</title>
		<link>http://blog.didierstevens.com/2007/07/23/cyberspeak-interview/#comment-11532</link>
		<dc:creator><![CDATA[keydet89]]></dc:creator>
		<pubDate>Mon, 23 Jul 2007 17:39:26 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/07/23/cyberspeak-interview/#comment-11532</guid>
		<description><![CDATA[Great interview!  I found it funny that Bret was asking questions that have been asked before, but there are just no answers available.

With malware that looks for certain applications to be run (ie, AV software, firewalls, etc), I wonder if anyone has seen malware that decrypts the values and either collects data, or gleans intel from the contents of the key...

Good job, Didier!

Harlan]]></description>
		<content:encoded><![CDATA[<p>Great interview!  I found it funny that Bret was asking questions that have been asked before, but there are just no answers available.</p>
<p>With malware that looks for certain applications to be run (ie, AV software, firewalls, etc), I wonder if anyone has seen malware that decrypts the values and either collects data, or gleans intel from the contents of the key&#8230;</p>
<p>Good job, Didier!</p>
<p>Harlan</p>
]]></content:encoded>
	</item>
</channel>
</rss>

